Mike Cohen (@scudette) 's Twitter Profile
Mike Cohen

@scudette

Digital Paleontologist, digging deeper

ID: 76611371

calendar_today23-09-2009 10:34:07

474 Tweet

779 Followers

170 Following

Velociraptor (@velocidex) 's Twitter Profile Photo

If you like us here, you'll LOVE us on Discord. Come join the smartest and most lively #DFIR community on the planet. discord.com/invite/YAU3vRE

If you like us here, you'll LOVE us on Discord.  Come join the smartest and most lively #DFIR community on the planet. 

discord.com/invite/YAU3vRE
Wes Lambert (@therealwlambert) 's Twitter Profile Photo

While there are many great articles that discuss logs to be sent to a SIEM, many don't mention filtering on the endpoint during investigations. This is an area in which Velociraptor excels. 🦖🚀 #FastForensicsBeforeFullSendIt #LogManagementMusts #SaveTheSIEM #SplunkCostBoss

Blake (@bmcder02) 's Twitter Profile Photo

If you missed VeloCon23, all talks are available on YouTube and the website. docs.velociraptor.app/presentations/… #dfir #cybersecurity #rapid7

Matthew Green 🌻 (@mgreen27) 's Twitter Profile Photo

Pushed out a Velociraptor artifact to scope some of the items in the SysAid post exploitation activity. docs.velociraptor.app/exchange/artif… Velociraptor

Matthew Green 🌻 (@mgreen27) 's Twitter Profile Photo

Sharing out my workshop from DEATHcon. mgreen27.notion.site/mgreen27/Veloc… Fun to showcase some of the similar workflows I do day to day. @Velocidex #dfir DEATHcon was put on by [email protected] Olaf Hartong 🦊🇦🇲 [email protected] its a really unique event - thank you!

Velociraptor (@velocidex) 's Twitter Profile Photo

Want a sneak peek at the upcoming Velociraptor v0.7.1? With awesome new capabilities like built in Sigma integration and enhanced notebook functionality, you will want to download the release candidate today and test it out. Be sure to log any bugs or issues through GitHub.

Velociraptor (@velocidex) 's Twitter Profile Photo

We're incredibly thankful to our wonderful community of contributors, testers and enthusiasts! Without you, Velociraptor wouldn't be what it is. To all of you, your family and friends, HAPPY THANKSGIVING!

We're incredibly thankful to our wonderful community of contributors, testers and enthusiasts!  Without you, Velociraptor wouldn't be what it is.

To all of you, your family and friends, HAPPY THANKSGIVING!
Matthew Green 🌻 (@mgreen27) 's Twitter Profile Photo

Thought I would make some posts for #100daysofyara. Not sure how often i'll post but good chance to test some triage workflow and build some pratical Velociraptor rules for automation :) In the example below I grabbed a NanoCore sample from MalwareBazaar -

Thought I would make some posts for #100daysofyara. Not sure how often i'll post but good chance to test some triage workflow and build some pratical Velociraptor rules for automation :)

In the example below I grabbed a NanoCore sample from MalwareBazaar -
Matthew Green 🌻 (@mgreen27) 's Twitter Profile Photo

Another #100daysofyara post - #R7Labs Source a couple of samples: bazaar.abuse.ch/browse/tag/Soc… Running Velociraptor Windows.Detection.Yara.Process in should detect on a running final payloads. I have focused on simple network connection & config filename strings.

Another #100daysofyara post - #R7Labs

Source a couple of samples:
bazaar.abuse.ch/browse/tag/Soc…

Running <a href="/velocidex/">Velociraptor</a>  Windows.Detection.Yara.Process in should detect on a running final payloads. I have focused on simple network connection &amp; config filename strings.
Matthew Green 🌻 (@mgreen27) 's Twitter Profile Photo

#100daysofyara targeting QuasarRAT via namespace strings observed in process memory and decompiled code. #R7Labs Velociraptor Windows.Detection.Yara.Process only returns one hit per process here as I added some groupings to minimise any FPs github.com/rapid7/Rapid7-…

#100daysofyara targeting QuasarRAT via namespace strings observed in process memory and decompiled code.  #R7Labs 

<a href="/velocidex/">Velociraptor</a>  Windows.Detection.Yara.Process only returns one hit per process here as I added some groupings to minimise any FPs

github.com/rapid7/Rapid7-…
Mike Cohen (@scudette) 's Twitter Profile Photo

Only a few days left to secure your early bird for our Velociraptor training in Singapore. This is a rare opportunity to learn about Velociraptor and how to deploy it effectively, develop VQL artifacts and actively hunt for adversaries. blackhat.com/asia-24/traini…

Mike Cohen (@scudette) 's Twitter Profile Photo

I was so excited about the new 0.72 release of Velociraptor I just could not wait to make a quick video to show you all the new features! #velociraptor #dfir #digitalforensics Check it out here youtube.com/watch?v=FwmFYm…

Stephan Berger (@malmoeb) 's Twitter Profile Photo

The incident started with a compromised server. When we extended the hunting to the entire network, we found traces of the "WayBack" campaign on a computer, which Yoroi documented almost exactly three years ago [1]. We also found the exact same code as in the blog on

The incident started with a compromised server. When we extended the hunting to the entire network, we found traces of the "WayBack" campaign on a computer, which <a href="/yoroisecurity/">Yoroi</a> documented almost exactly three years ago [1].

We also found the exact same code as in the blog on
Mike Cohen (@scudette) 's Twitter Profile Photo

We just re-published a cool blog post, on the Velociraptor Blog, by Chris Hayes from Reliance Forensics . The post illustrates the process of setting up Velociraptor using external certificates. docs.velociraptor.app/blog/2024/2024… Original post reliancecyber.com/secure-velocir…

Velociraptor (@velocidex) 's Twitter Profile Photo

Velociraptor release 0.73 is now available for testing! Read about all the cool new features here docs.velociraptor.app/blog/2024/2024… . An exciting new feature is built in timelining capability. Check the blog post here docs.velociraptor.app/blog/2024/2024…

Will Hunt @Stealthsploit@infosec.exchange (@stealthsploit) 's Twitter Profile Photo

Looking forward to speaking on a panel at the Rapid7 Take Command Summit. Register for free below as we talk about between pen testing, red teaming and the benefits of running regular security exercises. rapid7.brighttalk.com/?utm_source=re…

Velociraptor (@velocidex) 's Twitter Profile Photo

At AUSCERT conference we presented "Sigma and Detection Engineering with Velociraptor Velociraptor". Learn how to implement real time Sigma detection with forensic enhancements. Full presentation youtube.com/watch?v=3EBrpF… and slides docs.velociraptor.app/presentations/…